Detection and monitoring EU-developed

Gatewatcher NDR

Network detection and response platform that analyses traffic and metadata, prioritizes suspicious activity, and supports threat hunting and incident investigation.

By Gatewatcher · France

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Detection and monitoring
Developer or maintainer
Gatewatcher
Recorded country
France
Product model
Commercial
Deployment
Self-hosted / SaaS
Software license
Commercial license; full terms not publicly verified
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

Developed by French company Gatewatcher, which identifies its own NDR platform and has headquarters in France.

Reported capabilities

  • Analyzes network communications and metadata for behavioral threats.
  • Aggregates and prioritizes alerts for SOC investigation.
  • Vendor describes on-premises, SaaS and hybrid deployment options.

Scope and limits

Gatewatcher NDR is one platform; Decision Center, AIonIQ, sensors, and TAPs are not split as standalone CSIRT software here. Full product license terms were not publicly verified.

Inspect the research evidence 5 source observations
  1. identity / capabilities

    Current product page describes AIonIQ network analysis, metadata visibility, alert aggregation, triage and threat hunting.

    Read source
  2. origin / country / maintenance

    Official 2026 company statement calls Gatewatcher French, says it developed its NDR platform, and describes ongoing platform development.

    Read source
  3. country

    The official locations page lists Gatewatcher headquarters at La Défense, France.

    Read source
  4. deployment

    Vendor case page explicitly describes on-premises, SaaS and hybrid deployment of the commercial NDR solution.

    Read source
  5. license

    The official NDR offer presents commercial deployment but does not publish full customer software rights or product license terms in the reviewed page.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.

From Sigma rule to a tested detection